Hi Manoli,
Just a hind from my side, if you want to try with this.
In http://wiki.wireshark.org/CaptureFilters i have find the following filter :
(tcp[0:2] > 1500 and tcp[0:2] < 1550)
i have tried this but is not clear to me which values are acceptable after tcp[0:2] >.
as 0:2 are the bytes for source and dest ports, in my try source was 2&3 and dest 3&4.
Regards,
George
Απο: Manolis Katsidoniotis
<manoska@xxxxxxxxx>
Προς: Community support list for Wireshark <wireshark-users@xxxxxxxxxxxxx>
Στάλθηκε: 1:48 μ.μ. Πέμπτη, 13 Οκτωβρίου 2011
Θεμα: Re: [Wireshark-users] wireshark display filters: display range of termination ids in one command
thanks Martin
yes that's true
I put this more like an example of what I want to do
(of course I tried it since you never know how smart is a filter)
I saw some expressions of type
h248.termList
but am not aware of exactly how to use them.
Anyone who has even used them before?
thanks
Manolis
___________________________________________________________________________
Sent via: Wireshark-users mailing list <
wireshark-users@xxxxxxxxxxxxx>
Archives:
http://www.wireshark.org/lists/wireshark-usersUnsubscribe:
https://wireshark.org/mailman/options/wireshark-users mailto:
wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe